Proving You Are Compliant: Assessments, Audits and ISO Certification
AI Governance, Risk & Compliance Track · Certified AI Assurance and Audit Professional
Governance that cannot be evidenced does not exist as far as a regulator or auditor is concerned. This course is about producing assurance: running a Data Protection Impact Assessment that satisfies Rule 13, preparing for an independent data audit, building an AI management system to ISO/IEC 42001 and taking it through certification, and auditing someone else's AI governance credibly. It teaches the evidentiary standard directly — what constitutes evidence, what constitutes assertion, and why contemporaneous records beat reconstructed ones. Learners run both sides: producing assurance and auditing it, because the fastest way to write a defensible assessment is to have attacked several.
Learning objectives
- 01Run a DPIA that satisfies DPDP Rule 13 and withstands independent review
- 02Prepare an organisation for an independent data audit
- 03Build an AI management system conforming to ISO/IEC 42001
- 04Manage an ISO/IEC 42001 certification process end to end
- 05Audit an AI governance framework and produce defensible findings
- 06Distinguish evidence from assertion and remediate evidentiary weakness
15-module program
Full curriculum in preparation
This course is being written now by the ITHR editorial team. Join the waitlist and we'll notify you the moment the full syllabus, hands-on labs, and certification exam are live. No enrollment is accepted until publication.

